1. Who we are and the scope of this policy
Gro by Fusion Ventures provides a managed, AI-assisted Growth Agent service for businesses. In this policy, “Gro,” “we,” “us,” and “our” mean the Gro service and Fusion Ventures as its operator.
This policy applies to gro.expert visitors, prospective and current clients, authorized workspace users, people who contact us, and other individuals whose information a client lawfully provides or connects to Gro. A third-party platform's own privacy terms also apply to its services.
2. Information clients and users provide
Information provided directly to Gro may include:
- names, business names, roles, email addresses, phone or WhatsApp numbers, websites, enquiry details, and account information;
- business profiles, services, locations, goals, approved or prohibited claims, instructions, requests, approvals, and feedback;
- uploaded documents, logos, brand assets, content, messages, and other materials supplied for client work; and
- billing, service, and correspondence records associated with the client relationship.
3. Website, lead, and connected business information
Depending on the agreed service, Gro may process public website pages and metadata, website inventory and technical observations, enquiries and leads, chatbot or business messages, content and social-media information, and related operational records. We process connected information only where the client or an authorized user has supplied it, authorized access, or confirmed another lawful basis for its use.
Clients are responsible for having the rights, notices, permissions, and lawful grounds needed for customer, lead, employee, or other third-party information they provide to Gro.
4. Analytics, SEO, and performance information
Gro may process website traffic observations, page performance, acquisition sources, search queries, clicks, impressions, click-through rates, average search positions, SEO reviews, opportunities, recommendations, and report history. Missing data is treated as unavailable rather than represented as a measured zero.
5. Google Analytics and Search Console data
When an authorized administrator connects Google, Gro requests the user's Google account identity and email together with read-only access to the Google Analytics and Google Search Console properties the administrator selects. The integration does not request Gmail or Google Drive access.
For Google Analytics, Gro may retrieve property details and observations such as date, page path, active users, new users, sessions, and page or screen views. For Search Console, Gro may retrieve verified-site details and observations such as date, query, page, clicks, impressions, click-through rate, and average position.
We use this data to verify selected properties, analyze traffic and search visibility, explain page and query performance, and provide client-facing Growth Agent findings and human-supervised recommendations. Google data is not sold or used for advertising, credit decisions, or training a generalized AI model.
6. Google OAuth authorization and credentials
Google access begins only after an authorized user completes Google's consent process. The requested Analytics and Search Console scopes are read-only. A refresh credential is encrypted and stored server-side so an approved connection can continue to operate. Short-lived access credentials are used server-side and are not returned to the browser. OAuth state and verification records are temporary security records.
Authorized client or Fusion Ventures administrators can disconnect a client's selected property mappings. Where no dependent mappings remain, an authorized administrator can revoke the shared Google connection, which removes the stored refresh credential after revocation completes. A Google user may also revoke access through their Google Account. Disconnection or revocation may make connected features unavailable.
7. Growth Agent conversations and requests
Gro may store Growth Agent conversations, client requests, replies, approvals, status changes, assigned personnel, and operational event history so the managed team can respond and maintain an accountable service record. Private staff notes are restricted from client users.
8. AI-assisted processing and human supervision
Gro may use AI systems to assist with analysis, summarization, recommendations, Growth Agent responses, content preparation, and operational support. AI output may be combined with deterministic data analysis and review, refinement, or implementation by authorized Fusion Ventures personnel.
AI output can be incomplete, inaccurate, or unsuitable for a particular purpose. Gro does not promise perfect accuracy, guaranteed business outcomes, or fully autonomous execution. Where Google user data is involved, human access and provider processing are limited to what is permitted by the client's authorization, the connected user-facing service, security needs, applicable law, and Google's Limited Use requirements.
9. Cookies, sessions, and authentication
Gro uses cookies and similar browser storage where needed to authenticate users, maintain secure sessions, complete OAuth flows, remember limited interface state, prevent misuse, and operate the service. These technologies may store identifiers and technical details such as session state, browser or device information, IP address, timestamps, and security events. Gro does not obtain Google authorization merely through a website cookie.
10. How and why we use information
We use information as reasonably necessary to:
- respond to enquiries and establish or administer services;
- authenticate users and operate client workspaces;
- provide, configure, supervise, secure, support, and improve the relevant Gro service;
- analyze authorized business information and prepare reports, recommendations, content, and requested work;
- coordinate client requests, approvals, and delivery;
- prevent fraud, abuse, unauthorized access, and security incidents;
- maintain billing, audit, and operational records; and
- comply with law, enforce agreements, and resolve disputes.
These purposes support our contracts and service relationship, legitimate business and security interests, consent or authorization where required, and compliance with legal obligations. The applicable basis depends on the information and circumstances.
11. Service providers and subprocessors
Gro uses third-party providers only as required to provide, secure, operate, or improve the relevant service. Depending on the feature, these may include Supabase for database and authentication infrastructure, Vercel for application hosting, Google for authorized Analytics and Search Console access, and communications, automation, security, or other infrastructure providers. If a feature using an external AI/model provider is enabled, relevant information may be processed by that provider for the requested Gro functionality.
Not every provider receives every client's information. Providers are given only the information and access reasonably necessary for their role and remain subject to applicable contractual and legal duties. We may also disclose information to professional advisers, transaction counterparties, or authorities where reasonably necessary or legally required. Gro does not sell personal information.
12. Google API data and Limited Use
Gro's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including its Limited Use requirements. Google user data is used only to provide or improve the connected, user-facing Gro service as permitted.
We do not transfer Google user data except with the user's consent as needed to provide the connected feature, for security purposes, to comply with applicable law, or as otherwise permitted by Google's policy. Personnel and service providers handling that data must comply with these restrictions. Gro does not claim that Google has certified or endorsed the service.
13. International processing
Gro is operated from the United Arab Emirates and uses cloud services. Information may therefore be processed or stored in countries outside a client's country or the UAE where necessary to operate Gro and its service providers. We do not promise UAE-only data residency. We use reasonable safeguards and measures appropriate to the information and applicable legal requirements.
14. Security and incident handling
We use reasonable technical and organizational safeguards designed to protect information, including access controls and server-side protection for connection credentials. No internet or storage system is completely secure. Clients should protect their credentials and promptly report suspected unauthorized access. If a security incident requires notification, Gro will notify affected parties or authorities as required by applicable law.
15. Retention
We retain information only for as long as reasonably necessary for the relevant service and the purposes described above. The period depends on the type of information, the client relationship, operational and security needs, disputes, and legal obligations. We do not promise a fixed deletion period that the platform does not guarantee.
16. Service termination and deletion
When a service relationship ends, Gro may delete client data and connection credentials. We may retain information where reasonably necessary for legal obligations, billing or accounting, fraud and security records, audits, disputes or enforcement, and temporary technical backup retention. Information in backups may remain until those backups are securely overwritten through normal operations.
Clients may request deletion or Google disconnection by contacting us. We will evaluate the request after verifying authority and apply any legal, security, contractual, or technical exceptions.
17. Individual and client rights
Depending on applicable law, an individual may have rights to request access, correction, deletion, restriction, objection, portability, or withdrawal of consent, and may be able to complain to a competent authority. These rights are not absolute. We may verify identity and authority, and a business client may need to handle requests concerning information it controls. Privacy and deletion requests can be sent to the contact below.
18. Minimum age
Gro is a business service for users aged 18 or older. It is not intended for children. If you believe a person under 18 has provided personal information through Gro, please contact us.
19. Changes to this policy
We may update this policy as Gro, its integrations, or applicable requirements change. Material changes will be reflected on this page by updating the date above and, where required, providing additional notice or obtaining renewed consent before using Google user data for a new purpose.
20. Contact
Questions, privacy requests, deletion requests, and Google connection requests can be sent to info@fusionventuresglobal.com. Gro is operated by Fusion Ventures from Ras Al Khaimah, United Arab Emirates.